01 / Scope and current status
This Policy covers managed LunaEcho and its website.
This Privacy Policy applies to the LunaEcho Discord application operated by ShadowOkami, authorized pre-release testing, future managed LunaEcho services, and the LunaEcho pages on shadowokami.com.
LunaEcho is currently in pre-release and is not accepting public servers. Features not yet enabled do not collect their planned feature data. This Policy will be reviewed as features and managed access become available.
Discord separately processes information under the Discord Privacy Policy. This Policy does not replace Discord's policy.
02 / Controller and contact
Who is responsible for managed-service data?
ShadowOkami, based in Germany, is the operator and data controller for personal data processed by the managed LunaEcho service and LunaEcho website.
03 / Data we process
Only data needed for enabled functions.
Current pre-release operation
During authorized testing, LunaEcho may process and record:
- Discord user ID, server (guild) ID, interaction ID, and command name.
- Command options supplied to an enabled command when needed to perform the requested action.
- Command timing, success or failure, entitlement result, and technical error details.
- Basic bot startup information such as connected server count and the LunaEcho bot account ID.
The current application uses Discord's non-privileged Guilds intent. It does not receive Discord account passwords, authentication tokens, private direct-message history, or user IP addresses from Discord.
Data used by planned features
When a feature becomes available and is enabled by a server administrator, LunaEcho may process the following feature-specific records:
- Server configuration: server, channel, role, and permission identifiers; selected settings; language; and plan assignment.
- Moderation: affected user ID, moderator ID, reason, action type, timestamps, and case references.
- Tickets: ticket participants, channel identifiers, messages or transcripts intentionally included in a ticket, and ticket status.
- Leveling and rewards: user ID, activity-derived XP, rank, reward roles, and exclusions. Message content is not required merely to count eligible activity.
- Temporary voice: creator-hub, temporary-channel, owner, and permission identifiers needed to create and remove rooms.
- Server logging: selected Discord event metadata and identifiers for the event categories enabled by administrators.
- Music and automation: requested media metadata, queue state, automation rules, schedules, and execution results.
LunaEcho is not intended for sensitive personal data. Do not submit passwords, tokens, payment card details, health data, government identifiers, or other confidential information through bot commands, tickets, or configuration fields.
Website delivery data
When you visit the LunaEcho website, the server may process IP address, user agent, requested URL, response status, and timestamp to deliver the page, prevent abuse, and diagnose errors. The website does not intentionally use advertising trackers, analytics profiles, or marketing cookies.
04 / Why we process data
Operation, safety, support, and improvement.
We process data to:
- Respond to Discord commands and provide features selected by server administrators.
- Apply permissions, plan capabilities, quotas, and server configuration.
- Prevent abuse, investigate errors, secure the service, and maintain reliability.
- Provide support, handle privacy requests, and communicate material service changes.
- Meet legal obligations and enforce the LunaEcho Terms of Service.
Where the GDPR applies, processing is based as appropriate on performing the requested service or taking steps before providing it, our legitimate interests in operating and securing LunaEcho, compliance with legal obligations, and consent where consent is specifically requested.
05 / Sharing and service providers
We do not sell personal data.
We may share or make data available only as needed to:
- Discord: commands, responses, and app activity pass through Discord's platform.
- Infrastructure providers: hosting, storage, backup, security, and email providers may process data under appropriate contractual and confidentiality obligations.
- Payment providers: if paid managed access launches, a disclosed payment provider may process billing details. LunaEcho will not store full payment card numbers.
- Authorities or affected parties: when required by law or reasonably necessary to protect users, rights, safety, or service security.
LunaEcho does not sell personal data, build advertising profiles, or share Discord API data for targeted advertising.
06 / Retention and deletion
Data is kept only for a defined purpose.
- Pre-release operational interaction and error logs are retained for up to 30 days, unless a longer period is needed to investigate a security incident or meet a legal obligation.
- Managed Free server-log records are planned for a maximum of 7 days. Managed Complete server-log records are planned for a maximum of 90 days. Administrators may choose shorter periods where controls allow it.
- Ticket transcripts follow the applicable managed plan and administrator actions. Managed Free transcripts are planned for up to 7 days after closure.
- Server configuration, active moderation records, progression data, and automation settings are retained while the feature is active. After LunaEcho is removed, managed-service records are deleted or anonymized within 30 days unless earlier deletion is requested or retention is legally required.
- Website security logs are normally retained for up to 30 days.
Backups, if used, may retain deleted records for a limited recovery cycle and are protected from ordinary use until overwritten. Data may be retained longer only when necessary for legal claims, abuse prevention, or a binding legal obligation.
Security and international processing
Practical safeguards, without impossible promises.
We use measures appropriate to the service stage, including restricted credentials, secret redaction in structured logs, least-privilege Discord access, access controls, updates, and encrypted HTTPS connections for the website. No online system can guarantee absolute security.
Discord and infrastructure providers may process data in countries outside your own. Where required, we rely on lawful transfer mechanisms and provider safeguards. Discord's own transfers are described in its privacy documentation.
07 / Your rights and deletion requests
You can ask about or delete your data.
Depending on applicable law, you may have rights to access, correct, delete, restrict, or receive a copy of personal data, and to object to certain processing or withdraw consent. You may also lodge a complaint with your local data-protection authority.
Email service@shadowokami.de with the subject LunaEcho Data Request.
Include your Discord User ID and, for server-level records, the relevant Server ID. Do not send your password or token.
State whether you want access, correction, deletion, restriction, or another privacy action.
Complete a reasonable ownership or administrator verification if needed to protect other users and server data.
Server owners and authorized administrators may request deletion of managed guild configuration and feature records. Individual users may request deletion of records linked to their Discord User ID where we control that data. We will respond within the timeframe required by applicable law and explain if a lawful exception applies.
08 / Self-hosted installations
The self-hosted operator controls its data.
This Policy does not govern data processed only by an independent self-hosted LunaEcho installation. The person or organization running that installation decides its configuration, storage, retention, security, and legal basis and is responsible for providing its own privacy information where required.
If you are unsure whether you use managed or self-hosted LunaEcho, ask the administrator of the Discord server where the app is installed.
Children
LunaEcho is not directed to anyone below the minimum age required to use Discord in their country. If you believe data relating to an underage user has been processed, contact us so it can be reviewed and deleted where appropriate.
Policy updates
We may update this Policy as LunaEcho develops, providers change, or legal requirements evolve. The current version and effective date will remain available at this URL. Material changes affecting an available managed service will be communicated where practical.
09 / Privacy contact
Contact the LunaEcho operator.
For privacy questions, data requests, or concerns about how managed LunaEcho processes information, contact ShadowOkami:
service@shadowokami.deNever send your Discord password, authentication token, bot token, or backup codes.